PT-2022-8653 · Microstrategy · Microstrategy Web Sdk

Published

2022-05-12

·

Updated

2022-05-23

·

CVE-2020-22985

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions MicroStrategy Web SDK versions 10.11 and earlier
Description The issue allows remote unauthenticated attackers to execute arbitrary code via the key parameter to the getESRIExtraConfig task. This is a Cross-Site Scripting (XSS) issue.
Recommendations For MicroStrategy Web SDK versions 10.11 and earlier, update to a version later than 10.11 to resolve the issue. As a temporary workaround, consider restricting access to the getESRIExtraConfig task to minimize the risk of exploitation. Avoid using the key parameter in the affected task until the issue is resolved.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-22985

Affected Products

Microstrategy Web Sdk